2 ms·
I’ve only done a few JWT implementations so forgive my ignorance but isn’t this what “exp” and token refreshes are for? If you don’t want to maintain a central
by ryanmarsh 5y ago
I’ve only done a few JWT implementations so forgive my ignorance but isn’t this what “exp” and token refreshes are for?
If you don’t want to maintain a centralized session store and you don’t want long lived tokens just set the expiry to 90 seconds. When you attempt a refresh, if the user is logged out it will fail.
I’m really confused by the either/or of “hit central session store on every request” or “tokens that live five minute too long are bad mmmkay”.
- josephg 5y agoHuh? To track if the user is logged in (for longer than 90 seconds) you’ll need another token, used to refresh the JWT token. And you’ll need the normal session infrastructure to validate that anyway. That sounds like a very complex system to cache session tokens. You may as well just cache normal session tokens for 90 seconds in your application servers. Same result, less complexity.